Files
infix/dev/tunnels/index.html
T

2814 lines
53 KiB
HTML

<!DOCTYPE html><html lang="en" class="no-js"><head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="description" content="Infix Documentation">
<link rel="canonical" href="https://kernelkit.github.io/infix/dev/tunnels/">
<link rel="prev" href="../eth-counters/">
<link rel="next" href="../vpn/">
<link rel="icon" href="../assets/images/favicon.png">
<meta name="generator" content="mkdocs-1.6.1, mkdocs-material-9.7.3">
<title>Tunneling (L2/L3) - User's Guide</title>
<link rel="stylesheet" href="../assets/stylesheets/main.484c7ddc.min.css">
<link rel="stylesheet" href="../assets/stylesheets/palette.ab4e12ef.min.css">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&amp;display=fallback">
<style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
<link rel="stylesheet" href="../extra.css">
<script>__md_scope=new URL("..",location),__md_hash=e=>[...e].reduce(((e,_)=>(e<<5)-e+_.charCodeAt(0)),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
<link href="../assets/stylesheets/glightbox.min.css" rel="stylesheet"><script src="../assets/javascripts/glightbox.min.js"></script><style id="glightbox-style">
html.glightbox-open { overflow: initial; height: 100%; }
.gslide-title { margin-top: 0px; user-select: text; }
.gslide-desc { color: #666; user-select: text; }
.gslide-image img { background: black; }
.glightbox-clean .gslide-media { -webkit-box-shadow: none; box-shadow: none; }
.gscrollbar-fixer { padding-right: 15px; }
.gdesc-inner { font-size: 0.75rem; }
body[data-md-color-scheme="slate"] .gdesc-inner { background: var(--md-default-bg-color); }
body[data-md-color-scheme="slate"] .gslide-title { color: var(--md-default-fg-color); }
body[data-md-color-scheme="slate"] .gslide-desc { color: var(--md-default-fg-color); }
</style></head>
<body dir="ltr" data-md-color-scheme="default" data-md-color-primary="orange" data-md-color-accent="orange">
<input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
<input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
<label class="md-overlay" for="__drawer"></label>
<div data-md-component="skip">
<a href="#tunnel-configuration" class="md-skip">
Skip to content
</a>
</div>
<div data-md-component="announce">
</div>
<div data-md-color-scheme="default" data-md-component="outdated" hidden>
</div>
<header class="md-header md-header--shadow" data-md-component="header">
<nav class="md-header__inner md-grid" aria-label="Header">
<a href="https://kernelkit.org/" title="User's Guide" class="md-header__button md-logo" aria-label="User's Guide" data-md-component="logo">
<img src="../logo-plain.png" alt="logo">
</a>
<label class="md-header__button md-icon" for="__drawer">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3zm0 5h18v2H3zm0 5h18v2H3z"></path></svg>
</label>
<div class="md-header__title" data-md-component="header-title">
<div class="md-header__ellipsis">
<div class="md-header__topic">
<span class="md-ellipsis">
User's Guide
</span>
</div>
<div class="md-header__topic" data-md-component="header-topic">
<span class="md-ellipsis">
Tunneling (L2/L3)
</span>
</div>
</div>
</div>
<form class="md-header__option" data-md-component="palette">
<input class="md-option" data-md-color-media="(prefers-color-scheme: light)" data-md-color-scheme="default" data-md-color-primary="orange" data-md-color-accent="orange" aria-label="Switch to dark mode" type="radio" name="__palette" id="__palette_0">
<label class="md-header__button md-icon" title="Switch to dark mode" for="__palette_1" hidden>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="m17.75 4.09-2.53 1.94.91 3.06-2.63-1.81-2.63 1.81.91-3.06-2.53-1.94L12.44 4l1.06-3 1.06 3zm3.5 6.91-1.64 1.25.59 1.98-1.7-1.17-1.7 1.17.59-1.98L15.75 11l2.06-.05L18.5 9l.69 1.95zm-2.28 4.95c.83-.08 1.72 1.1 1.19 1.85-.32.45-.66.87-1.08 1.27C15.17 23 8.84 23 4.94 19.07c-3.91-3.9-3.91-10.24 0-14.14.4-.4.82-.76 1.27-1.08.75-.53 1.93.36 1.85 1.19-.27 2.86.69 5.83 2.89 8.02a9.96 9.96 0 0 0 8.02 2.89m-1.64 2.02a12.08 12.08 0 0 1-7.8-3.47c-2.17-2.19-3.33-5-3.49-7.82-2.81 3.14-2.7 7.96.31 10.98 3.02 3.01 7.84 3.12 10.98.31"></path></svg>
</label>
<input class="md-option" data-md-color-media="(prefers-color-scheme: dark)" data-md-color-scheme="slate" data-md-color-primary="black" data-md-color-accent="orange" aria-label="Switch to light mode" type="radio" name="__palette" id="__palette_1">
<label class="md-header__button md-icon" title="Switch to light mode" for="__palette_0" hidden>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 7a5 5 0 0 1 5 5 5 5 0 0 1-5 5 5 5 0 0 1-5-5 5 5 0 0 1 5-5m0 2a3 3 0 0 0-3 3 3 3 0 0 0 3 3 3 3 0 0 0 3-3 3 3 0 0 0-3-3m0-7 2.39 3.42C13.65 5.15 12.84 5 12 5s-1.65.15-2.39.42zM3.34 7l4.16-.35A7.2 7.2 0 0 0 5.94 8.5c-.44.74-.69 1.5-.83 2.29zm.02 10 1.76-3.77a7.131 7.131 0 0 0 2.38 4.14zM20.65 7l-1.77 3.79a7.02 7.02 0 0 0-2.38-4.15zm-.01 10-4.14.36c.59-.51 1.12-1.14 1.54-1.86.42-.73.69-1.5.83-2.29zM12 22l-2.41-3.44c.74.27 1.55.44 2.41.44.82 0 1.63-.17 2.37-.44z"></path></svg>
</label>
</form>
<script>var palette=__md_get("__palette");if(palette&&palette.color){if("(prefers-color-scheme)"===palette.color.media){var media=matchMedia("(prefers-color-scheme: light)"),input=document.querySelector(media.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");palette.color.media=input.getAttribute("data-md-color-media"),palette.color.scheme=input.getAttribute("data-md-color-scheme"),palette.color.primary=input.getAttribute("data-md-color-primary"),palette.color.accent=input.getAttribute("data-md-color-accent")}for(var[key,value]of Object.entries(palette.color))document.body.setAttribute("data-md-color-"+key,value)}</script>
<label class="md-header__button md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"></path></svg>
</label>
<div class="md-search" data-md-component="search" role="dialog">
<label class="md-search__overlay" for="__search"></label>
<div class="md-search__inner" role="search">
<form class="md-search__form" name="search">
<input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
<label class="md-search__icon md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"></path></svg>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11z"></path></svg>
</label>
<nav class="md-search__options" aria-label="Search">
<a href="javascript:void(0)" class="md-search__icon md-icon" title="Share" aria-label="Share" data-clipboard data-clipboard-text="" data-md-component="search-share" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M18 16.08c-.76 0-1.44.3-1.96.77L8.91 12.7c.05-.23.09-.46.09-.7s-.04-.47-.09-.7l7.05-4.11c.54.5 1.25.81 2.04.81a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3c0 .24.04.47.09.7L8.04 9.81C7.5 9.31 6.79 9 6 9a3 3 0 0 0-3 3 3 3 0 0 0 3 3c.79 0 1.5-.31 2.04-.81l7.12 4.15c-.05.21-.08.43-.08.66 0 1.61 1.31 2.91 2.92 2.91s2.92-1.3 2.92-2.91A2.92 2.92 0 0 0 18 16.08"></path></svg>
</a>
<button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12z"></path></svg>
</button>
</nav>
</form>
<div class="md-search__output">
<div class="md-search__scrollwrap" tabindex="0" data-md-scrollfix>
<div class="md-search-result" data-md-component="search-result">
<div class="md-search-result__meta">
Initializing search
</div>
<ol class="md-search-result__list" role="presentation"></ol>
</div>
</div>
</div>
</div>
</div>
<div class="md-header__source">
<a href="https://github.com/kernelkit/infix/" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2025 Fonticons, Inc.--><path d="M439.6 236.1 244 40.5c-5.4-5.5-12.8-8.5-20.4-8.5s-15 3-20.4 8.4L162.5 81l51.5 51.5c27.1-9.1 52.7 16.8 43.4 43.7l49.7 49.7c34.2-11.8 61.2 31 35.5 56.7-26.5 26.5-70.2-2.9-56-37.3L240.3 199v121.9c25.3 12.5 22.3 41.8 9.1 55-6.4 6.4-15.2 10.1-24.3 10.1s-17.8-3.6-24.3-10.1c-17.6-17.6-11.1-46.9 11.2-56v-123c-20.8-8.5-24.6-30.7-18.6-45L142.6 101 8.5 235.1C3 240.6 0 247.9 0 255.5s3 15 8.5 20.4l195.6 195.7c5.4 5.4 12.7 8.4 20.4 8.4s15-3 20.4-8.4l194.7-194.7c5.4-5.4 8.4-12.8 8.4-20.4s-3-15-8.4-20.4"></path></svg>
</div>
<div class="md-source__repository">
kernelkit/infix
</div>
</a>
</div>
</nav>
</header>
<div class="md-container" data-md-component="container">
<main class="md-main" data-md-component="main">
<div class="md-main__inner md-grid">
<div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation">
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--primary" aria-label="Navigation" data-md-level="0">
<label class="md-nav__title" for="__drawer">
<a href="https://kernelkit.org/" title="User's Guide" class="md-nav__button md-logo" aria-label="User's Guide" data-md-component="logo">
<img src="../logo-plain.png" alt="logo">
</a>
User's Guide
</label>
<div class="md-nav__source">
<a href="https://github.com/kernelkit/infix/" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 7.1.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2025 Fonticons, Inc.--><path d="M439.6 236.1 244 40.5c-5.4-5.5-12.8-8.5-20.4-8.5s-15 3-20.4 8.4L162.5 81l51.5 51.5c27.1-9.1 52.7 16.8 43.4 43.7l49.7 49.7c34.2-11.8 61.2 31 35.5 56.7-26.5 26.5-70.2-2.9-56-37.3L240.3 199v121.9c25.3 12.5 22.3 41.8 9.1 55-6.4 6.4-15.2 10.1-24.3 10.1s-17.8-3.6-24.3-10.1c-17.6-17.6-11.1-46.9 11.2-56v-123c-20.8-8.5-24.6-30.7-18.6-45L142.6 101 8.5 235.1C3 240.6 0 247.9 0 255.5s3 15 8.5 20.4l195.6 195.7c5.4 5.4 12.7 8.4 20.4 8.4s15-3 20.4-8.4l194.7-194.7c5.4-5.4 8.4-12.8 8.4-20.4s-3-15-8.4-20.4"></path></svg>
</div>
<div class="md-source__repository">
kernelkit/infix
</div>
</a>
</div>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href=".." class="md-nav__link">
<span class="md-ellipsis">
Introduction
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_2">
<label class="md-nav__link" for="__nav_2" id="__nav_2_label" tabindex="0">
<span class="md-ellipsis">
CLI
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_2_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_2">
<span class="md-nav__icon md-icon"></span>
CLI
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../cli/introduction/" class="md-nav__link">
<span class="md-ellipsis">
Introduction
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/configure/" class="md-nav__link">
<span class="md-ellipsis">
Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/keybindings/" class="md-nav__link">
<span class="md-ellipsis">
Keybindings
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/netcalc/" class="md-nav__link">
<span class="md-ellipsis">
Network Calculator
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/tcpdump/" class="md-nav__link">
<span class="md-ellipsis">
Network Monitoring
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/quick/" class="md-nav__link">
<span class="md-ellipsis">
Quickstart Guide
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/text-editor/" class="md-nav__link">
<span class="md-ellipsis">
Text Editor
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../cli/upgrade/" class="md-nav__link">
<span class="md-ellipsis">
Upgrading
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="../container/" class="md-nav__link">
<span class="md-ellipsis">
Docker Containers
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--active md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_4" checked>
<label class="md-nav__link" for="__nav_4" id="__nav_4_label" tabindex="0">
<span class="md-ellipsis">
Networking
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_4_label" aria-expanded="true">
<label class="md-nav__title" for="__nav_4">
<span class="md-nav__icon md-icon"></span>
Networking
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../networking/" class="md-nav__link">
<span class="md-ellipsis">
Overview
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../iface/" class="md-nav__link">
<span class="md-ellipsis">
Common Settings
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../bridging/" class="md-nav__link">
<span class="md-ellipsis">
Bridging
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../lag/" class="md-nav__link">
<span class="md-ellipsis">
Link Aggregation
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../ethernet/" class="md-nav__link">
<span class="md-ellipsis">
Ethernet Interfaces
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../ip/" class="md-nav__link">
<span class="md-ellipsis">
IP Addressing
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../routing/" class="md-nav__link">
<span class="md-ellipsis">
Routing
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../firewall/" class="md-nav__link">
<span class="md-ellipsis">
Firewall Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../qos/" class="md-nav__link">
<span class="md-ellipsis">
Quality of Service
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../eth-counters/" class="md-nav__link">
<span class="md-ellipsis">
RMON Counters
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--active">
<input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
<label class="md-nav__link md-nav__link--active" for="__toc">
<span class="md-ellipsis">
Tunneling (L2/L3)
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<a href="./" class="md-nav__link md-nav__link--active">
<span class="md-ellipsis">
Tunneling (L2/L3)
</span>
</a>
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#generic-routing-encapsulation-gre" class="md-nav__link">
<span class="md-ellipsis">
Generic Routing Encapsulation (GRE)
</span>
</a>
<nav class="md-nav" aria-label="Generic Routing Encapsulation (GRE)">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#basic-gre-configuration" class="md-nav__link">
<span class="md-ellipsis">
Basic GRE Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#gretap-configuration" class="md-nav__link">
<span class="md-ellipsis">
GRETAP Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ospf-over-gre" class="md-nav__link">
<span class="md-ellipsis">
OSPF over GRE
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#advanced-tunnel-settings" class="md-nav__link">
<span class="md-ellipsis">
Advanced Tunnel Settings
</span>
</a>
<nav class="md-nav" aria-label="Advanced Tunnel Settings">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#time-to-live-ttl" class="md-nav__link">
<span class="md-ellipsis">
Time To Live (TTL)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#type-of-service-tos" class="md-nav__link">
<span class="md-ellipsis">
Type of Service (ToS)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#path-mtu-discovery-gre-only" class="md-nav__link">
<span class="md-ellipsis">
Path MTU Discovery (GRE only)
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#virtual-extensible-local-area-network-vxlan" class="md-nav__link">
<span class="md-ellipsis">
Virtual eXtensible Local Area Network (VXLAN)
</span>
</a>
<nav class="md-nav" aria-label="Virtual eXtensible Local Area Network (VXLAN)">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#basic-vxlan-configuration" class="md-nav__link">
<span class="md-ellipsis">
Basic VXLAN Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#vxlan-with-custom-udp-port" class="md-nav__link">
<span class="md-ellipsis">
VXLAN with Custom UDP Port
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_4_12">
<label class="md-nav__link" for="__nav_4_12" id="__nav_4_12_label" tabindex="0">
<span class="md-ellipsis">
VPN Tunnels
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="2" aria-labelledby="__nav_4_12_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_4_12">
<span class="md-nav__icon md-icon"></span>
VPN Tunnels
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../vpn/" class="md-nav__link">
<span class="md-ellipsis">
Overview
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../vpn-wireguard/" class="md-nav__link">
<span class="md-ellipsis">
WireGuard
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="../wifi/" class="md-nav__link">
<span class="md-ellipsis">
Wireless LAN (WiFi)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_5">
<label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
<span class="md-ellipsis">
Services
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_5">
<span class="md-nav__icon md-icon"></span>
Services
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../discovery/" class="md-nav__link">
<span class="md-ellipsis">
Device Discovery
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../dhcp/" class="md-nav__link">
<span class="md-ellipsis">
DHCP Server
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../ntp/" class="md-nav__link">
<span class="md-ellipsis">
NTP Server
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_6">
<label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
<span class="md-ellipsis">
System
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_6">
<span class="md-nav__icon md-icon"></span>
System
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../boot/" class="md-nav__link">
<span class="md-ellipsis">
Boot Procedure
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../system/" class="md-nav__link">
<span class="md-ellipsis">
Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../nacm/" class="md-nav__link">
<span class="md-ellipsis">
Access Control (NACM)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../hardware/" class="md-nav__link">
<span class="md-ellipsis">
Hardware Info &amp; Status
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../management/" class="md-nav__link">
<span class="md-ellipsis">
Management
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../keystore/" class="md-nav__link">
<span class="md-ellipsis">
Keystore
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../syslog/" class="md-nav__link">
<span class="md-ellipsis">
Syslog Support
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../support/" class="md-nav__link">
<span class="md-ellipsis">
Support Data
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../upgrade/" class="md-nav__link">
<span class="md-ellipsis">
Upgrade
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_7">
<label class="md-nav__link" for="__nav_7" id="__nav_7_label" tabindex="0">
<span class="md-ellipsis">
Scripting
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_7_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_7">
<span class="md-nav__icon md-icon"></span>
Scripting
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../scripting/" class="md-nav__link">
<span class="md-ellipsis">
Introduction
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../scripting-sysrepocfg/" class="md-nav__link">
<span class="md-ellipsis">
Legacy Scripting
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../scripting-netconf/" class="md-nav__link">
<span class="md-ellipsis">
NETCONF Scripting
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../scripting-restconf/" class="md-nav__link">
<span class="md-ellipsis">
RESTCONF Scripting
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../scripting-prod/" class="md-nav__link">
<span class="md-ellipsis">
Production Testing
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_8">
<label class="md-nav__link" for="__nav_8" id="__nav_8_label" tabindex="0">
<span class="md-ellipsis">
Developer's Corner
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_8_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_8">
<span class="md-nav__icon md-icon"></span>
Developer's Corner
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../branding/" class="md-nav__link">
<span class="md-ellipsis">
Branding &amp; Releases
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../developers-guide/" class="md-nav__link">
<span class="md-ellipsis">
Developer's Guide
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../override-package/" class="md-nav__link">
<span class="md-ellipsis">
Developing with Buildroot
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../netboot/" class="md-nav__link">
<span class="md-ellipsis">
Netboot HowTo
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../testing/" class="md-nav__link">
<span class="md-ellipsis">
Regression Testing
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../test-arch/" class="md-nav__link">
<span class="md-ellipsis">
Test System Architecture
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../virtual/" class="md-nav__link">
<span class="md-ellipsis">
Virtual Environments
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../vpd/" class="md-nav__link">
<span class="md-ellipsis">
Vital Product Data (VPD)
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="../license/" class="md-nav__link">
<span class="md-ellipsis">
Origin &amp; Licensing
</span>
</a>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc">
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#generic-routing-encapsulation-gre" class="md-nav__link">
<span class="md-ellipsis">
Generic Routing Encapsulation (GRE)
</span>
</a>
<nav class="md-nav" aria-label="Generic Routing Encapsulation (GRE)">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#basic-gre-configuration" class="md-nav__link">
<span class="md-ellipsis">
Basic GRE Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#gretap-configuration" class="md-nav__link">
<span class="md-ellipsis">
GRETAP Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ospf-over-gre" class="md-nav__link">
<span class="md-ellipsis">
OSPF over GRE
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#advanced-tunnel-settings" class="md-nav__link">
<span class="md-ellipsis">
Advanced Tunnel Settings
</span>
</a>
<nav class="md-nav" aria-label="Advanced Tunnel Settings">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#time-to-live-ttl" class="md-nav__link">
<span class="md-ellipsis">
Time To Live (TTL)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#type-of-service-tos" class="md-nav__link">
<span class="md-ellipsis">
Type of Service (ToS)
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#path-mtu-discovery-gre-only" class="md-nav__link">
<span class="md-ellipsis">
Path MTU Discovery (GRE only)
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#virtual-extensible-local-area-network-vxlan" class="md-nav__link">
<span class="md-ellipsis">
Virtual eXtensible Local Area Network (VXLAN)
</span>
</a>
<nav class="md-nav" aria-label="Virtual eXtensible Local Area Network (VXLAN)">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#basic-vxlan-configuration" class="md-nav__link">
<span class="md-ellipsis">
Basic VXLAN Configuration
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#vxlan-with-custom-udp-port" class="md-nav__link">
<span class="md-ellipsis">
VXLAN with Custom UDP Port
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-content" data-md-component="content">
<nav class="md-path" aria-label="Navigation">
<ol class="md-path__list">
<li class="md-path__item">
<a href=".." class="md-path__link">
<span class="md-ellipsis">
Introduction
</span>
</a>
</li>
<li class="md-path__item">
<a href="../networking/" class="md-path__link">
<span class="md-ellipsis">
Networking
</span>
</a>
</li>
</ol>
</nav>
<article class="md-content__inner md-typeset">
<h1 id="tunnel-configuration">Tunnel Configuration<a class="headerlink" href="#tunnel-configuration" title="Permanent link"></a></h1>
<p>Infix supports multiple tunnel encapsulation protocols for connecting
remote networks or devices across an IP backbone. Tunnels encapsulate
packets within IP datagrams, allowing traffic to traverse intermediate
networks transparently.</p>
<div class="admonition tip">
<p class="admonition-title">Important</p>
<p>When issuing <code>leave</code> to activate your changes, remember to also save
your settings, <code>copy running-config startup-config</code>. See the <a href="../cli/introduction/">CLI
Introduction</a> for a background.</p>
</div>
<h2 id="generic-routing-encapsulation-gre">Generic Routing Encapsulation (GRE)<a class="headerlink" href="#generic-routing-encapsulation-gre" title="Permanent link"></a></h2>
<p>GRE tunnels provide a simple and efficient method to encapsulate various
network layer protocols over IP networks. Infix supports both IPv4 and
IPv6 tunnels in two modes:</p>
<ul>
<li><strong>GRE (Layer 3):</strong> Point-to-point IP tunnel for routing protocols and
routed traffic</li>
<li><strong>GRETAP (Layer 2):</strong> Ethernet tunnel for bridging Layer 2 networks</li>
</ul>
<div class="admonition tip">
<p class="admonition-title">Tip</p>
<p>If you name your tunnel interface <code>greN</code> or <code>gretapN</code>, where <code>N</code> is a
number, the CLI infers the interface type automatically.</p>
</div>
<h3 id="basic-gre-configuration">Basic GRE Configuration<a class="headerlink" href="#basic-gre-configuration" title="Permanent link"></a></h3>
<p>A basic GRE tunnel for routing between two sites:</p>
<pre class="cli"><code>admin@example:/&gt; <b>configure</b>
admin@example:/config/&gt; <b>edit interface gre0</b>
admin@example:/config/interface/gre0/&gt; <b>set gre local 192.168.3.1 remote 192.168.3.2</b>
admin@example:/config/interface/gre0/&gt; <b>set ipv4 address 10.255.0.1 prefix-length 30</b>
admin@example:/config/interface/gre0/&gt; <b>leave</b>
admin@example:/&gt;
</code></pre>
<p>This creates a Layer 3 tunnel between 192.168.3.1 and 192.168.3.2 using
the outer IP addresses, with the tunnel itself using 10.255.0.0/30 for
the inner IP addressing.</p>
<h3 id="gretap-configuration">GRETAP Configuration<a class="headerlink" href="#gretap-configuration" title="Permanent link"></a></h3>
<p>GRETAP tunnels operate at Layer 2, allowing bridging across the tunnel:</p>
<pre class="cli"><code>admin@example:/&gt; <b>configure</b>
admin@example:/config/&gt; <b>edit interface gretap0</b>
admin@example:/config/interface/gretap0/&gt; <b>set type gretap</b>
admin@example:/config/interface/gretap0/&gt; <b>set gre local 192.168.3.1 remote 192.168.3.2</b>
admin@example:/config/interface/gretap0/&gt; <b>leave</b>
admin@example:/&gt;
</code></pre>
<p>GRETAP interfaces can be added to a bridge, bridging local and remote Ethernet
segments. See the <a href="../bridging/">Bridge Configuration</a>
for more on bridges.</p>
<h3 id="ospf-over-gre">OSPF over GRE<a class="headerlink" href="#ospf-over-gre" title="Permanent link"></a></h3>
<p>GRE tunnels are commonly used to carry dynamic routing protocols like
OSPF across networks that don't support multicast or where you want to
create a virtual topology different from the physical network.</p>
<p>Example topology: Two sites connected via a GRE tunnel, running OSPF to
exchange routes.</p>
<p><strong>Site A configuration:</strong></p>
<pre class="cli"><code>admin@siteA:/&gt; <b>configure</b>
admin@siteA:/config/&gt; <b>edit interface gre0</b>
admin@siteA:/config/interface/gre0/&gt; <b>set gre local 203.0.113.1 remote 203.0.113.2</b>
admin@siteA:/config/interface/gre0/&gt; <b>set ipv4 address 10.255.0.1 prefix-length 30</b>
admin@siteA:/config/interface/gre0/&gt; <b>set ipv4 forwarding</b>
admin@siteA:/config/interface/gre0/&gt; <b>end</b>
admin@siteA:/config/&gt; <b>edit routing control-plane-protocol ospfv2 name default ospf</b>
admin@siteA:/config/routing/…/ospf/&gt; <b>set area 0.0.0.0 interface gre0</b>
admin@siteA:/config/routing/…/ospf/&gt; <b>leave</b>
admin@siteA:/&gt;
</code></pre>
<p><strong>Site B configuration:</strong></p>
<pre class="cli"><code>admin@siteB:/&gt; <b>configure</b>
admin@siteB:/config/&gt; <b>edit interface gre0</b>
admin@siteB:/config/interface/gre0/&gt; <b>set gre local 203.0.113.2 remote 203.0.113.1</b>
admin@siteB:/config/interface/gre0/&gt; <b>set ipv4 address 10.255.0.2 prefix-length 30</b>
admin@siteB:/config/interface/gre0/&gt; <b>set ipv4 forwarding</b>
admin@siteB:/config/interface/gre0/&gt; <b>end</b>
admin@siteB:/config/&gt; <b>edit routing control-plane-protocol ospfv2 name default ospf</b>
admin@siteB:/config/routing/…/ospf/&gt; <b>set area 0.0.0.0 interface gre0</b>
admin@siteB:/config/routing/…/ospf/&gt; <b>leave</b>
admin@siteB:/&gt;
</code></pre>
<p>Once configured, OSPF will establish a neighbor relationship through the
tunnel and exchange routes between the sites. For more info on OSPF
configuration, see <a href="../routing/#ospfv2-routing">OSPFv2 Routing</a>.</p>
<div class="admonition note">
<p class="admonition-title">Note</p>
<p>Consider adjusting MTU on the tunnel interface to account for GRE
overhead (typically 24 bytes for IPv4, 44 bytes for IPv6) to avoid
fragmentation issues.</p>
</div>
<h3 id="advanced-tunnel-settings">Advanced Tunnel Settings<a class="headerlink" href="#advanced-tunnel-settings" title="Permanent link"></a></h3>
<p>All tunnel types support common parameters for controlling tunnel behavior
and performance.</p>
<h4 id="time-to-live-ttl">Time To Live (TTL)<a class="headerlink" href="#time-to-live-ttl" title="Permanent link"></a></h4>
<p>The TTL setting controls the Time To Live value for the outer tunnel packets.
By default, tunnels use a fixed TTL of 64, which allows packets to traverse
multiple hops between tunnel endpoints.</p>
<pre class="cli"><code>admin@example:/config/&gt; <b>edit interface gre0</b>
admin@example:/config/interface/gre0/&gt; <b>set gre ttl 255</b>
admin@example:/config/interface/gre0/&gt; <b>leave</b>
</code></pre>
<p>Valid values are 1-255, or the special value <code>inherit</code> which copies the TTL
from the encapsulated packet.</p>
<div class="admonition tip">
<p class="admonition-title">Important</p>
<p>The <code>inherit</code> mode can cause problems with routing protocols like OSPF
that use TTL=1 for their packets. For tunnels carrying routing protocols,
always use a fixed TTL value (typically 64 or 255).</p>
</div>
<h4 id="type-of-service-tos">Type of Service (ToS)<a class="headerlink" href="#type-of-service-tos" title="Permanent link"></a></h4>
<p>The ToS setting controls QoS marking for tunnel traffic:</p>
<pre class="cli"><code>admin@example:/config/&gt; <b>edit interface gre0</b>
admin@example:/config/interface/gre0/&gt; <b>set gre tos 0x10</b>
admin@example:/config/interface/gre0/&gt; <b>leave</b>
</code></pre>
<p>Valid values are 0-255 for fixed ToS/DSCP marking, or <code>inherit</code> (default)
to copy the ToS value from the encapsulated packet.</p>
<h4 id="path-mtu-discovery-gre-only">Path MTU Discovery (GRE only)<a class="headerlink" href="#path-mtu-discovery-gre-only" title="Permanent link"></a></h4>
<p>The <code>pmtu-discovery</code> setting can be used to control the Path MTU Discovery on
GRE tunnels. When enabled (default), the tunnel respects the Don't Fragment
(DF) bit and performs PMTU discovery:</p>
<pre class="cli"><code>admin@example:/config/&gt; <b>edit interface gre0</b>
admin@example:/config/interface/gre0/&gt; <b>set gre pmtudisc false</b>
admin@example:/config/interface/gre0/&gt; <b>leave</b>
</code></pre>
<p>Disabling PMTU discovery may be necessary in networks with broken ICMP
filtering but can lead to suboptimal performance and fragmentation.</p>
<h2 id="virtual-extensible-local-area-network-vxlan">Virtual eXtensible Local Area Network (VXLAN)<a class="headerlink" href="#virtual-extensible-local-area-network-vxlan" title="Permanent link"></a></h2>
<p>VXLAN is a network virtualization technology that encapsulates Layer 2
Ethernet frames within Layer 4 UDP datagrams. It uses a 24-bit segment
ID, termed VXLAN Network Identifier (VNI), allowing up to 16 million
isolated networks.</p>
<p>Infix supports both IPv4 and IPv6 for VXLAN tunnel endpoints.</p>
<h3 id="basic-vxlan-configuration">Basic VXLAN Configuration<a class="headerlink" href="#basic-vxlan-configuration" title="Permanent link"></a></h3>
<div class="admonition tip">
<p class="admonition-title">Tip</p>
<p>If you name your VXLAN interface <code>vxlanN</code>, where <code>N</code> is a number, the
CLI infers the interface type automatically.</p>
</div>
<pre class="cli"><code>admin@example:/&gt; <b>configure</b>
admin@example:/config/&gt; <b>edit interface vxlan100</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan local 192.168.3.1</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan remote 192.168.3.2</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan vni 100</b>
admin@example:/config/interface/vxlan100/&gt; <b>leave</b>
admin@example:/&gt;
</code></pre>
<p>The VNI uniquely identifies the VXLAN segment and must match on both
tunnel endpoints.</p>
<h3 id="vxlan-with-custom-udp-port">VXLAN with Custom UDP Port<a class="headerlink" href="#vxlan-with-custom-udp-port" title="Permanent link"></a></h3>
<p>The default VXLAN UDP destination port is 4789 (IANA assigned). In some
cases you may need to use a different port:</p>
<pre class="cli"><code>admin@example:/&gt; <b>configure</b>
admin@example:/config/&gt; <b>edit interface vxlan100</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan local 192.168.3.1</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan remote 192.168.3.2</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan vni 100</b>
admin@example:/config/interface/vxlan100/&gt; <b>set vxlan remote-port 8472</b>
admin@example:/config/interface/vxlan100/&gt; <b>leave</b>
admin@example:/&gt;
</code></pre>
<p>The remote-port setting allows interoperability with systems using
non-standard VXLAN ports.</p>
<div class="admonition note">
<p class="admonition-title">Note</p>
<p>VXLAN tunnels also support the <code>ttl</code> and <code>tos</code> settings described in
the <a href="#advanced-tunnel-settings">Advanced Tunnel Settings</a> section above.</p>
</div>
</article>
</div>
<script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
</div>
</main>
<footer class="md-footer">
<div class="md-footer-meta md-typeset">
<div class="md-footer-meta__inner md-grid">
<div class="md-copyright">
<div class="md-copyright__highlight">
Copyright © 2022-2025 The KernelKit Team
</div>
</div>
</div>
</div>
</footer>
</div>
<div class="md-dialog" data-md-component="dialog">
<div class="md-dialog__inner md-typeset"></div>
</div>
<div class="md-progress" data-md-component="progress" role="progressbar"></div>
<script id="__config" type="application/json">{"annotate": null, "base": "..", "features": ["toc.follow", "navigation.path", "navigation.instant", "navigation.instant.progress", "navigation.tracking", "navigation.indexes", "search.highlight", "search.share", "content.code.copy", "content.code.annotate", "content.footnote.tooltips"], "search": "../assets/javascripts/workers/search.2c215733.min.js", "tags": null, "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}, "version": {"provider": "mike"}}</script>
<script src="../assets/javascripts/bundle.79ae519e.min.js"></script>
<script id="init-glightbox">const lightbox = GLightbox({"touchNavigation": true, "loop": false, "zoomable": true, "draggable": true, "openEffect": "zoom", "closeEffect": "zoom", "slideEffect": "slide"});
document$.subscribe(()=>{ lightbox.reload(); });
</script></body></html>